Executive brief
The Enable CORS plugin for WordPress, which allows websites to manage cross-origin resource sharing, contains a backdoor. This vulnerability allows an unauthorized person to gain remote access to the website, potentially leading to full site takeover, data theft, or the injection of malicious content. Business operations could be severely impacted by unauthorized changes to the site or the loss of customer trust.
Technical details
The Enable CORS plugin for WordPress (versions up to and including 2.0.3) contains an unauthenticated backdoor. The vulnerability is associated with CWE-321 (Use of Hard-coded Cryptographic Key), suggesting that a hard-coded secret may be used to authenticate administrative or sensitive actions. An attacker can exploit this over the network without any prior authentication to gain access to the site and execute arbitrary payloads. The issue is resolved in version 2.0.4.
Affected products
- Dev Kabir Enable CORS <= 2.0.3
Timeline
- 2026-06-08: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-06-18: advisory: Patchstack published advisory details
- 2026-06-26: advisory: NVD published CVE record